Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3752-1

Опубликовано: 24 окт. 2024
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 fixes the following issues:

Update to version 2.46.0 (bsc#1231039).

  • CVE-2024-40866
  • CVE-2024-44187

Already fixed in version 2.44.3:

  • CVE-2024-27838
  • CVE-2024-27851

Already fixed in version 2.44.2:

  • CVE-2024-27834
  • CVE-2024-27808
  • CVE-2024-27820
  • CVE-2024-27833

Already fixed in version 2.44.1:

  • CVE-2024-23222
  • CVE-2024-23206
  • CVE-2024-23213
  • CVE-2024-23271

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP6
WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1
libwebkit2gtk-4_0-37-2.46.0-150600.12.12.1
libwebkitgtk-6_0-4-2.46.0-150600.12.12.1
typelib-1_0-JavaScriptCore-4_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit2-4_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit2WebExtension-4_0-2.46.0-150600.12.12.1
webkit2gtk-4_0-injected-bundles-2.46.0-150600.12.12.1
webkit2gtk3-soup2-devel-2.46.0-150600.12.12.1
webkitgtk-6_0-injected-bundles-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6
WebKitGTK-4.1-lang-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_1-0-2.46.0-150600.12.12.1
libwebkit2gtk-4_1-0-2.46.0-150600.12.12.1
typelib-1_0-JavaScriptCore-4_1-2.46.0-150600.12.12.1
typelib-1_0-WebKit2-4_1-2.46.0-150600.12.12.1
typelib-1_0-WebKit2WebExtension-4_1-2.46.0-150600.12.12.1
webkit2gtk-4_1-injected-bundles-2.46.0-150600.12.12.1
webkit2gtk3-devel-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
typelib-1_0-JavaScriptCore-6_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit-6_0-2.46.0-150600.12.12.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.46.0-150600.12.12.1
webkit2gtk4-devel-2.46.0-150600.12.12.1
openSUSE Leap 15.6
WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
WebKitGTK-4.1-lang-2.46.0-150600.12.12.1
WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_0-18-32bit-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_1-0-2.46.0-150600.12.12.1
libjavascriptcoregtk-4_1-0-32bit-2.46.0-150600.12.12.1
libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1
libwebkit2gtk-4_0-37-2.46.0-150600.12.12.1
libwebkit2gtk-4_0-37-32bit-2.46.0-150600.12.12.1
libwebkit2gtk-4_1-0-2.46.0-150600.12.12.1
libwebkit2gtk-4_1-0-32bit-2.46.0-150600.12.12.1
libwebkitgtk-6_0-4-2.46.0-150600.12.12.1
typelib-1_0-JavaScriptCore-4_0-2.46.0-150600.12.12.1
typelib-1_0-JavaScriptCore-4_1-2.46.0-150600.12.12.1
typelib-1_0-JavaScriptCore-6_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit-6_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit2-4_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit2-4_1-2.46.0-150600.12.12.1
typelib-1_0-WebKit2WebExtension-4_0-2.46.0-150600.12.12.1
typelib-1_0-WebKit2WebExtension-4_1-2.46.0-150600.12.12.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.46.0-150600.12.12.1
webkit-jsc-4-2.46.0-150600.12.12.1
webkit-jsc-4.1-2.46.0-150600.12.12.1
webkit-jsc-6.0-2.46.0-150600.12.12.1
webkit2gtk-4_0-injected-bundles-2.46.0-150600.12.12.1
webkit2gtk-4_1-injected-bundles-2.46.0-150600.12.12.1
webkit2gtk3-devel-2.46.0-150600.12.12.1
webkit2gtk3-minibrowser-2.46.0-150600.12.12.1
webkit2gtk3-soup2-devel-2.46.0-150600.12.12.1
webkit2gtk3-soup2-minibrowser-2.46.0-150600.12.12.1
webkit2gtk4-devel-2.46.0-150600.12.12.1
webkit2gtk4-minibrowser-2.46.0-150600.12.12.1
webkitgtk-6_0-injected-bundles-2.46.0-150600.12.12.1

Описание

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A maliciously crafted webpage may be able to fingerprint the user.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. Processing web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки

Описание

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-4.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:WebKitGTK-6.0-lang-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-4_0-18-2.46.0-150600.12.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP6:libjavascriptcoregtk-6_0-1-2.46.0-150600.12.12.1

Ссылки
Уязвимость SUSE-SU-2024:3752-1